Patentable/Patents/US-12132732
US-12132732

Dynamic allocation of network slice-specific credentials

PublishedOctober 29, 2024
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

A credential manager imports credentials for a network slice in response to deployment of the network slice. The credentials are not known to other network slices. A repository is configured to store the credentials and protect the credentials based on credential protection policies that are defined by a service profile of the network slice. The repository is implemented in the credential manager, an authentication, authorization, and accounting (AAA) server, or other location. Properties of the credentials are modified in response to a modification trigger and the credentials are withdrawn in response to a withdrawal trigger.

Patent Claims
12 claims

Legal claims defining the scope of protection, as filed with the USPTO.

3

3. The apparatus of claim 1, wherein the at least one processor is implemented in a credential manager and wherein the repository is implemented in at least one of the credential manager and an authentication, authorization, and accounting (AAA) server.

4

4. The apparatus of claim 1, wherein the credentials stored in the repository are protected according to at least one of encryption, access control, storage isolation, and integrity protection policies associated with a Single-Network Slice Selection Assistance Information (S-NSSAI) as defined in the service profile of the network slice.

5

5. The apparatus of claim 2, wherein the modification trigger comprises at least one of compromising the credentials, loss of the credentials, expiration of the credentials, a change in a security state or environment of the network slice, a change in a regulation or policy.

6

6. The apparatus of claim 2, wherein the property of the credentials comprises at least one of a value of the credentials, the credential protection policy, usage of the credentials for at least one of authentication and protecting traffic associated with the S-NSSAI, and subscriber authentication flags associate with the S-NSSAI that indicate whether primary or secondary authentication is used.

7

7. The apparatus of claim 2, wherein the processor is configured to trigger, in response to the modification trigger, modification of at least one of network slice authentication flags, traffic protection options on a network function, and wherein the processor is configured to trigger the modification of the credentials on a user equipment in response to the modification trigger.

8

8. The apparatus of claim 2, wherein the withdrawal trigger comprises at least one of termination of the network slice, disassociation of the S-NSSAI from the network slice, and disassociation of the tenant from the network slice.

9

9. The apparatus of claim 2, wherein the processor is configured to trigger, in response to the withdrawal trigger, update of at least one of network slice authentication flags, traffic protection options, and wherein the processor is configured to trigger removal of the credentials from a user equipment in response to the withdrawal trigger.

11

11. The method of claim 10, wherein the repository is implemented in at least one of a credential manager and an authentication, authorization, and accounting (AAA) server.

12

12. The method of claim 10, wherein protecting the credentials comprises protecting the credentials according to at least one of encryption, access control, storage isolation, and integrity protection policies associated with a Single-Network Slice Selection Assistance Information (S-NSSAI) defined in the service profile of the network slice.

15

15. The method of claim 14, wherein the modification trigger comprises at least one of compromising the credentials, loss of the credentials, expiration of the credentials, a change in a security state or environment of the network slice, a change in a regulation or policy.

16

16. The method of claim 14, wherein the property of the credentials comprises at least one of a value of the credentials, the credential protection policy, usage of the credentials for at least one of authentication and protecting traffic associated with a Single-Network Slice Selection Assistance Information (S-NSSAI) and subscriber authentication flags associated with the S-NSSAI that indicate whether primary or secondary authentication is used.

19

19. The method of claim 18, wherein the withdrawal trigger comprises at least one of termination of the network slice, disassociated of the S-NSSAI from the network slice, and disassociated of the tenant from the network slice.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

June 24, 2019

Publication Date

October 29, 2024

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Dynamic allocation of network slice-specific credentials” (US-12132732). https://patentable.app/patents/US-12132732

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.